Malicious PDF — malware analysis report

Static analysis result for SHA-256 551389731526b954…

MALICIOUS

PDF

20.1 KB Created: 2019-05-01 17:32:24 +01:00 Authoring application: mPDF 5.7
MD5: bf29bbd9de02d0436bf979ff94533baa SHA-1: 65db52d2f9996ee985f1ac8ef670c369f6f9a3b9 SHA-256: 551389731526b954ba44a9692d06524aabd7e11442709acf0df6b4eca863808c
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1190 Exploit Public-Facing Application

The PDF contains a large number of embedded external links, identified as a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a multitude of URLs hosted on kiteeearpdf.myhome.cx, which could be used for SEO spam or to serve further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kiteeearpdf.myhome.cx/4f217f210f211f216f211/Nickel-and-Dimed-On-Not-Getting-By-in-America-by-Barbara-Ehrenreich.pdf
    • http://kiteeearpdf.myhome.cx/6f214f219f214f218f214/Nickel-and-Dimed-On-Not-Getting-By-in-America-by-Barbara-Ehrenreich.pdf
    • http://kiteeearpdf.myhome.cx/2f218f215f218f219f216/Bright-sided-How-the-Relentless-Promotion-of-Positive-Thinking-Has-Undermined-America-by-Barbara-Ehrenreich.pdf
    • http://kiteeearpdf.myhome.cx/2f215f211f212f217f218/For-Her-Own-Good-Two-Centuries-of-the-Experts-Advice-to-Women-by-Barbara-Ehrenreich.pdf
    • http://kiteeearpdf.myhome.cx/3f217f210f215f216f214/The-Worst-Years-of-Our-Lives-Irreverent-Notes-from-a-Decade-of-Greed-by-Barbara-Ehrenreich.pdf
    • http://kiteeearpdf.myhome.cx/2f217f219f212f211f216/Natural-Causes-An-Epidemic-of-Wellness-the-Certainty-of-Dying-and-Killing-Ourselves-to-Live-Longer-by-Barbara-Ehrenreich.pdf
    • http://kiteeearpdf.myhome.cx/2f210f211f213f217f210/The-Gladys-Elegies-by-Barbara-Kathleen-Nickel.pdf
    • http://kiteeearpdf.myhome.cx/3f211f214f210f216f215/Complaints-amp-Disorders-Complaints-and-Disorders-The-Sexual-Politics-of-Sickness-by-Barbara-Ehrenreich.pdf
    • http://kiteeearpdf.myhome.cx/3f216f210f216f218f214/Another-America-Otra-America-by-Barbara-Kingsolver.pdf
    • http://kiteeearpdf.myhome.cx/5f212f210f211f212f214/Politician-s-Dilemma-Building-State-Capacity-in-Latin-America-by-Barbara-Geddes.pdf
    • http://kiteeearpdf.myhome.cx/9f219f218f214f216f215/Der-Weg-zur-Quelle-Leben-und-Tod-in-Pal-stina-by-Ben-Ehrenreich.pdf
    • http://kiteeearpdf.myhome.cx/4f214f214f218f214f215/Other-Voices-Other-Vistas-Short-Stories-from-Africa-China-India-Japan-and-Latin-America-by-Barbara-H-Solomon.pdf
    • http://kiteeearpdf.myhome.cx/1f211f215f212f217f214f219/Nickel-and-Dime-by-Gary-Soto.pdf
    • http://kiteeearpdf.myhome.cx/1f215f216f216f210/Nickel-Mountain-by-John-Gardner.pdf
    • http://kiteeearpdf.myhome.cx/1f211f215f212f217f215f210/The-Wooden-Nickel-by-Alisha-Paige.pdf
    • http://kiteeearpdf.myhome.cx/6f215f211f218f219f210/Cry-for-a-Nickel-Die-for-a-Dime-by-Woody-Haut.pdf
    • http://kiteeearpdf.myhome.cx/1f211f215f212f218f215f213/Nickel-Wife-by-Joyce-Dingwell.pdf
    • http://kiteeearpdf.myhome.cx/1f211f215f212f217f218f216/Buffalo-Nickel-by-Floyd-Salas.pdf
    • http://kiteeearpdf.myhome.cx/9f214f217f216f211f213/Christianity-for-the-Unbeliever-by-Joshua-Nickel.pdf
    • http://kiteeearpdf.myhome.cx/1f216f212f212f216f216/Night-of-the-Homework-Zombies-by-Scott-Nickel.pdf